Grafana is an open-source platform for monitoring and observability.
Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token.
By enabling the "url_login" configuration option (disabled by default), a JWT might be sent to data sources. If an attacker has access to the data source, the leaked token could be used to authenticate to Grafana.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GRAFANA
Published: 2023-04-26T13:47:16.914Z
Updated: 2024-08-02T05:49:11.313Z
Reserved: 2023-03-14T11:11:01.304Z
Link: CVE-2023-1387
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-26T14:15:09.430
Modified: 2024-11-21T07:39:05.150
Link: CVE-2023-1387
Redhat